Exception Register

May 10, 2026 ยท View on GitHub

This document tracks approved deviations from security policies for Hex registry infrastructure.

Active Exceptions

IDExceptionJustificationApproved ByExpiryReview Date
------

Exception Process

Requesting an Exception

  1. Document the specific policy deviation required
  2. Provide justification explaining why the exception is necessary
  3. Describe compensating controls or mitigations in place
  4. Propose an expiry date or review cadence

Approval Criteria

CriterionDescription
Business justificationClear need for the exception
Risk assessmentUnderstanding of security impact
Compensating controlsMitigations to reduce risk
Time-boundDefined expiry or review date

Review Process

  • Exceptions are reviewed on their specified review date
  • Expired exceptions must be renewed or the deviation corrected
  • All active exceptions are reviewed during security audits

Archived Exceptions

IDExceptionExpiryResolution
----